Back to skill

Security audit

Supabase DB

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Supabase database-admin purpose, but it gives an agent powerful database access with weak safeguards for privileged credentials and destructive commands.

Install only if you are comfortable giving the skill administrative Supabase database access. Prefer a least-privilege or project-scoped key where possible, protect SUPABASE_URL like a secret-bearing setting, avoid sensitive text in vector-search queries unless OpenAI processing is acceptable, and manually review any raw SQL, update, delete, upsert, or RPC command before it runs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/supabase.sh:5
Finding

Privileged Supabase credentials can be transmitted to an arbitrary or plaintext endpoint

Content
View full analysis
&2 exit 1 fi if [[ -z "${SUPABASE_SERVICE_KEY:-}" ]]; then echo "Error: SUPABASE_SERVICE_KEY not set" >&2 exit 1 fi REST_URL="${SUPABASE_URL}/rest/v1" RPC_URL="${SUPABASE_URL}/rest/v1/rpc" ``` ```bash # Make API request api_request() { local method="$1" local endpoint="$2" local data="${3:-}" local extra_headers=("${@:4}") local args=( -s -X "$method" -H "apikey: ${SUPABASE_SERVICE_KEY}" -H "Authorization: Bearer ${SUPABASE_SERVICE_KEY}" -H "Content-Type: application/json" -H "Prefer: return=representation" ) for header in "${extra_headers[@]:-}"; do [[ -n "$header" ]] && args+=(-H "$header") done if [[ -n "$data" ]]; then args+=(-d "$data") fi curl "${args[@]}" "$endpoint" } ``` ### Technical Analysis `SUPABASE_URL` is only checked for emptiness. The script does not parse the value, require HTTPS, reject embedded credentials, or verify that the destination is an expected Supabase project. Every API request places `SUPABASE_SERVICE_KEY` in both the `apikey` and bearer authorization headers. Consequently, if the environment variable is maliciously or accidentally configured with an attacker-controlled URL, the privileged key is sent directly to that server. An `http://` URL would additionally expose the key and request data to network interception. This is especially sensitive because the documentation states that the service-role key bypasses Supabase Row Level Security. ### Attack Path 1. An attacker gains influence over the process environment, deployment configuration, `.env` source ...[truncated 1359 chars]
Remediation
View remediation
&2 exit 1 ;; esac ``` For self-hosted installations, replace the broad pattern with a configurable but explicit hostname allowlist rather than accepting arbitrary URLs. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/supabase.sh:113
Finding

Update and delete safety checks can be bypassed with non-predicate options

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` Because command substitution runs `build_filters` in a subshell, returning both the filter text and predicate state should be implemented carefully—for example, by having the parser populate caller-visible variables without command substitution, or by returning structured output that the caller explicitly validates. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The setup instructions tell users to export a Supabase service role key, and later note that it bypasses RLS, but this is not presented as a strong security warning. A service role key grants broad administrative access, so exposing or routinely using it in an agent-driven skill significantly raises the risk of unauthorized reads, writes, or mass data loss if the agent is misused or the environment is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises raw SQL, update, upsert, and delete capabilities but does not prominently warn users that these operations can modify or permanently destroy data. In the context of an agent skill, users may invoke these actions through natural language, which increases the chance of unintended destructive actions if privilege and confirmation boundaries are unclear.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states that embeddings default to OpenAI's model but does not clearly warn that document or query text may be sent to a third-party provider for processing. In a database and document-search skill, this can lead to unintentional disclosure of sensitive content, especially if users assume all processing stays within Supabase.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents a delete operation without any caution that it can permanently remove data, and it encourages use with a Supabase service role key that bypasses RLS. In an agent-executed context, this increases the chance of accidental or overly broad destructive actions, especially if parameters are generated from natural-language instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The raw SQL query capability is presented with examples including CREATE TABLE, but there is no warning that arbitrary SQL can alter schema, destroy data, or bypass intended application controls when used with a privileged key. Because the skill is specifically designed for database administration and accepts free-form SQL, misuse or prompt-driven mistakes could cause significant integrity or availability impact.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script presents itself as a Supabase CLI, but its vector-search path also transmits user-provided query text to OpenAI to generate embeddings. That mismatch creates a meaningful transparency and data-handling risk because operators may assume all processing stays within Supabase and unknowingly send sensitive search content to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The vector-search command sends raw user query text to OpenAI without a prominent user-facing warning at the point of use. If users submit secrets, internal document snippets, or regulated data as queries, that information is externally disclosed outside the stated Supabase boundary.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The hardcoded use of the OpenAI endpoint confirms that vector search depends on a third-party external service rather than remaining solely within Supabase. In skill context, this increases risk because administrators may grant the script broad database access via a service key while overlooking that search inputs are also exfiltrated to an outside provider.

Content

Scanner excerpt · scripts/supabase.sh (reported line 362)May include surrounding context.

sh
fi
    
    local embedding
    embedding=$(curl -s https://api.openai.com/v1/embeddings \
        -H "Authorization: Bearer ${OPENAI_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "{\"input\": $(printf '%s' "$query" | jq -Rs .), \"model\": \"text-embedding-ada-002\"}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The hardcoded use of the OpenAI endpoint confirms that vector search depends on a third-party external service rather than remaining solely within Supabase. In skill context, this increases risk because administrators may grant the script broad database access via a service key while overlooking that search inputs are also exfiltrated to an outside provider.

Content

Scanner excerpt · scripts/supabase.sh (reported line 362)May include surrounding context.

sh
fi
    
    local embedding
    embedding=$(curl -s https://api.openai.com/v1/embeddings \
        -H "Authorization: Bearer ${OPENAI_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "{\"input\": $(printf '%s' "$query" | jq -Rs .), \"model\": \"text-embedding-ada-002\"}" \

Static analysis

No suspicious patterns detected.